7 ms·
This is a dangerous power grab. RPKI and social security ( nobody wants to peer with a idiot ) are already here and many things are in development. The FCC an
by coretx 2y ago
This is a dangerous power grab.
RPKI and social security ( nobody wants to peer with a idiot ) are already here and many things are in development.
The FCC and by extension the USA should GTFO and let the multi stakeholder models do their work.
- awaythrow999 2y agoIt's a power grab in tge same sense as when people got outraged that everything on HTTP suddenly had to have PKI and x509 certificates. While x509 is shit, ASN1 an outdated mess, nobody would today argue that TLS is bad.
- akira2501 2y ago> HTTP suddenly had to have PKI and x509 certificates. Was that because the government mandated that outcome?
- immibis 2y agoThat was definitely a power grab. Suddenly CAs had all the power. The ONLY reason we ever accepted a browser-mandated transition to TLS is that Let's Encrypt started existing. Without Let's Encrypt, this would have the effect of requiring every website operator to pay money to a CA, even with full self-hosting. When Let's Encrypt eventually stops behaving in an altruistic fashion, we'll stop doing near-mandatory TLS.
- sidewndr46 2y agoI would argue that with mandated TLS, there is no such thing as "full self-hosting" any longer if you want to be part of the web. Everyone is beholden to a CA somehow
- superkuh 2y agoEveryone's home internet connection now is very fast. They are very capable of hosting a static website of files in folders from home as a human person without CAs being involved. And it's much safer than, say, running Chrome w/javascript on and visiting a random website.
- immibis 2y agoExcept they aren't fully capable, because it's considered insecure and certain features are disabled, and all options to bypass this was deliberately made extremely difficult to bypass. It would be even worse if Mozilla's original plan had succeeded - making TLS completely mandatory on the Internet, so that http URLs would only be accepted for localhost and RFC1918 IP addresses.
- superkuh 2y agoYes, people stuck using a corporate browser might have trouble accessing non-corporate websites because of those browser's loses of capability. It sucks. HTTP webservers are fully capable but realistically every human person should do HTTP+HTTPS for the best of both worlds. Regardless, for HTTP there's an entire 'year 2000's web' worth of people out there using browsers that can access the non-corporate web. As the corporate web diverges with things like stateful HTTP extensions, UDP HTTP, and CA TLS only implementations (if not spec) there's no need to switch to a niche protocol like Gemini. Just making a normal website on the web is enough to bring back the old small web environment. As a human person not operating under a profit motive and just doing things for kicks this is just fine. A silver lining like how usenet is actually good again now that most people don't get it from their ISP.
- mike_hock 2y agoASN1 >>> some "readable" "plain text" crap. Though ASN1 inside base64, now that's hilarious!
- superkuh 2y agoTLS is not bad, but CA TLS is for the vast majority of human persons on the internet. It makes things very fragile and only last a couple years max without constant mantainence. This is okay for commerce and institutions but for human websites it is devestating. Human persons just don't have the same use cases or threat models as a megacorp and cargo culting megacorp style solutions to everyone is bad.
- foobiekr 2y agoThe threat model of plain http is about the user (and injected content) and not the server. Plain http is a threat to users. Has it really been so many years since people used to do tcp injections and walk around coffee shops or whatever returning results faster than the internet server and injecting goatse? You guys have forgotten who tls protects.
- superkuh 2y agoNope, you've just applied your application model of the web to the web as a whole. Most websites are not actually applications and the risk of "injected content" to people with javascript turned off is very, very low. The risk comes from the absolutely bonkers corporate/institutional use cases of automatically executing all random unverified programs sent to you. When you remove this crazy use case suddenly all the problems (and bonkers requirements) go away. Seeing a goatse is not the end of the world and actual MITM injection attacks like you describe are rather rare now. I miss when wifi use to be open and that issue mattered.
- foobiekr 2y agoThe average user does not have JavaScript turned off. Plain http sites are a risk to their users.
- cookiengineer 2y agoWell, that's kinda what you get when Russian and China Telecom constantly claim networks that aren't theirs to begin with. Some form of cryptographic ownership verification is the logical next step to prevent these things from happening. Though I'd prefer a decentralized/pinned approach when single point of failure (read as: CA) is the alternative.
- karma_pharmer 2y agoRussian and China Telecom constantly claim networks that aren't theirs to begin with. ... and coretx's "nobody wants to peer with an idiot" is clearly not working here. These networks are still being peered with. Maybe the regulators should start by regulating only international peering.
- nine_k 2y agoBecause they are not idiots. Were they idiots, they'd quickly lose to someone more clueful. The idea to regulate only international peering looks best so far. It's much like (m)any other regulations that are only present on the border between countries, and are absent inside.
- alfons_foobar 2y ago> only international peering The concepts of "national" and "international" don't map very well to the internet. Many companies run multiple ASes, and many companies are peering at IXPs all over the world...
- a_random_canuck 2y agoThey need to. Honestly we need a way to completely segregate Chinese and Russian networks off, as well as anyone who peers with them. They are using our open networks to brazenly attack us in broad daylight… it’s time to fight back.
- deleted 2y ago
- benprone 2y agoSo you’ll peddle a conservative power grab by private interests over a public one. “…a idiot…” You’re right about peering with idiots. A shame social media is so popular since that’s about all it gets us. Peering with idiots.